Two cybersecurity firms independently found separate ways to make Atlassian’s Rovo assistant collect Jira or Confluence data accessible to a signed-in user and send it to an external server. One route has been confirmed closed, but it remains unclear whether that fix affected the separate attack involving instructions hidden in content Rovo reads. Varonis Threat Labs named the link-based technique RovoBlast. The `rovoChatPrompt` URL parameter could preload attacker-written instructions into Rovo Chat. A single click by an authenticated user was enough for Rovo to execute those instructions with the user’s permissions and send data to an attacker-controlled server. Varonis demonstrated the exfiltration of a private API key from Confluence, while Bugcrowd said the technique was also tested against Jira and data accessible through SharePoint and Outlook connectors. Atlassian fixed the link flaw server-side on July 8, 2026, and the reporter validated the fix. Bugcrowd rated the report P2 and awarded a $6,000 bounty. Customers do not need to install a software update to address this attack route. PromptArmor described a separate indirect prompt-injection path in which attacker-controlled instructions are concealed in a document or other content Rovo is asked to use. In the firm’s published example, a user uploaded a document carrying hidden instructions and asked Rovo to organize Jira tickets. Rovo searched Jira and Confluence, appended the results to an attacker-controlled URL and opened it, exposing ticket and page contents in the attacker’s server logs without a separate human approval step for the exfiltration. PromptArmor said disabling Rovo’s web-search setting did not stop the attack because the outbound request used a separate URL-retrieval capability. The firm disclosed the issue to Atlassian on May 23, 2026, and later published after saying further communication had stopped. As of August 8, neither disclosure had a CVE identifier, and neither reported evidence that the techniques had been used against a real organization. The demonstrated access was limited to data available through the victim’s permissions; the reports did not show a tenant-wide authorization bypass. Rovo is enabled by default for apps on Standard, Premium and Enterprise plans, but administrators can review access by app and user group, tighten permissions and connector scope, and avoid treating the web-search setting alone as a complete security boundary. Somali organizations using Jira or Confluence can focus their review on who has Rovo access and how far each account’s permissions extend, because the demonstrated risk turns an account’s legitimate reach into a path for unauthorized data transfer.